F5-K000138444: High severity nginx vulnerability
Published Feb 14, 2024
·Updated
When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate.
Affected Software
2 affected componentsFixes available
F5 NGINX Plus=31
31
F5 NGINX Open Source=1.25.3
1.25.4
Event History
Feb 14, 2024
Advisory Published
via F5·01:33 PM
Frequently Asked Questions
1
What is the severity of F5-K000138444?
The severity of F5-K000138444 has been classified as critical due to potential service disruptions.
2
How do I fix F5-K000138444?
To fix F5-K000138444, update to the patched versions NGINX Plus 31 or NGINX Open Source 1.25.4.
3
What specifically causes the issue in F5-K000138444?
The issue in F5-K000138444 is caused by undisclosed requests that can lead to the termination of NGINX worker processes.
4
Which NGINX versions are affected by F5-K000138444?
F5-K000138444 affects NGINX Plus version 31 and NGINX Open Source version 1.25.3.
5
Is there a workaround for F5-K000138444 until I can apply a fix?
Currently, no official workaround is provided for F5-K000138444, and it is recommended to apply the updates as soon as possible.